morpheus
Aliases: HellCat
- First seen
- 2020-03-15 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-04 21:31:13
- Profile updated
- 2026-07-07 13:55:03
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us country_code:de country_code:ru
Context
Morpheus, also known as HellCat, is a remote access trojan used by threat actors to conduct cyber-espionage activities. It targets sensitive sectors such as financial services and government entities, often leading to the unauthorized access and theft of sensitive information.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Morpheus_Auto (yara-rule)
Reports & references
- ransomlook.io — Morpheus (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Morpheus (report)
- zscaler.com — Technical Analysis Transferloader (report)
- sentinelone.com — Hellcat And Morpheus Two Brands One Payload As Ransomware Affiliates Drop Identical Code (report)
- picussecurity.com — Hellcat Ransomware (report)